Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > rocksolid.shared.security > #66 > unrolled thread

remote code exec in dnsmasq

Started byAnonymous <poster@anon.com>
First post2021-01-20 05:30 -0800
Last post2021-01-21 08:38 +0100
Articles 6 — 4 participants

Back to article view | Back to rocksolid.shared.security


Contents

  remote code exec in dnsmasq Anonymous <poster@anon.com> - 2021-01-20 05:30 -0800
    Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-20 16:00 +0100
      Re: remote code exec in dnsmasq "AnonUser" <anonuser@rocksolidbbs.com.remove-32i-this> - 2021-01-20 18:47 +0000
        Re: remote code exec in dnsmasq Guest <guest@retrobbs.rocksolidbbs.com> - 2021-01-20 13:25 -0500
          Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-21 08:40 +0100
        Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-21 08:38 +0100

#66 — remote code exec in dnsmasq

FromAnonymous <poster@anon.com>
Date2021-01-20 05:30 -0800
Subjectremote code exec in dnsmasq
Message-ID<opsec.767.1iv4v3@anon.com>
https://www.jsof-tech.com/wp-content/uploads/2021/01/DNSpooq_Technical-Whitepaper.pdf

CVE-2020-25681: Heap-based buffer overflow with arbitrary overwrite

Thank fuck I am on tor and don't rely on DNS.

-- 
Posted on def2

[toc] | [next] | [standalone]


#67

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2021-01-20 16:00 +0100
Message-ID<ru9gi5$el1$1@shakotay.alphanet.ch>
In reply to#66
Anonymous <poster@anon.com> wrote:
> Thank fuck I am on tor and don't rely on DNS.

However, your IP router might well run dnsmasq.

[toc] | [prev] | [next] | [standalone]


#68

From"AnonUser" <anonuser@rocksolidbbs.com.remove-32i-this>
Date2021-01-20 18:47 +0000
Message-ID<a5c363938980657088f898e6d9482201$1@retrobbs.i2p>
In reply to#67
  To: Marc SCHAEFER
Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs.
-- 
Posted on RetroBBS
retrobbs.i2p

[toc] | [prev] | [next] | [standalone]


#69

FromGuest <guest@retrobbs.rocksolidbbs.com>
Date2021-01-20 13:25 -0500
Message-ID<rua126$cic$1@def5.org>
In reply to#68
>However, your IP router might well run dnsmasq.

Yes, that is true. I consider my router to be compromised anyway, and don't trust it. 
I don't see though how this would compromise my tor setup. The authority tor nodes are hardcoded into tor (with their ip addresses), and everything after should be safe I think. I could be wrong of course.

There was some way to use dns to deanomize tor users, but it worked differently (see : https://nakedsecurity.sophos.com/2016/10/05/unmasking-tor-users-with-dns/ )

>Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs.

If you can find out the system of your router, it should be easy to verify.

Or you run the attack against your own router (bit more effort).

--
Posted on def3

[toc] | [prev] | [next] | [standalone]


#71

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2021-01-21 08:40 +0100
Message-ID<rubb4k$vmp$1@shakotay.alphanet.ch>
In reply to#69
Guest <guest@retrobbs.rocksolidbbs.com> wrote:
> Yes, that is true. I consider my router to be compromised anyway, and don't trust it. 

If you have a firewall behind your router, protecting the router from
accessing your internal network, then you are presumably safe, if using
tor only.

Else, the router could use vulnerabilities in your OS software
(including any printer, webcam, etc) or in one of your applications or
configuration.

:)

[toc] | [prev] | [next] | [standalone]


#70

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2021-01-21 08:38 +0100
Message-ID<rubb1i$vbi$1@shakotay.alphanet.ch>
In reply to#68
AnonUser <anonuser@rocksolidbbs.com.remove-32i-this> wrote:
> Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs.

I would assume that if it has a Linux or BSD OS, and it has a DNS
functionnality, it is dnsmasq.

[toc] | [prev] | [standalone]


Back to top | Article view | rocksolid.shared.security


csiph-web